Job Summary:The Identity and Access Management (IAM) Linux Engineering role supports MUFG Bank's governance, safety, and soundness objectives by maintaining secure, compliant Linux access controls. This engineering position helps ensure IAM Linux capabilities align with regulatory requirements, industry standards, internal policies, and established risk tolerances.
The ideal candidate has strong Linux engineering experience, can operate at an AVP level, and is interested in broadening their IAM skillset across Identity Governance and Administration (IGA), Microsoft Entra ID, and privileged access technologies. This role requires close collaboration with global security, business, and technology teams.
Responsibilities:- Implement and maintain Centrify least-privilege access controls and role-based access models
- Automate operational and control processes using scripting
- Enforce IAM policies across Linux, Active Directory, and cloud-integrated environments
- Support Centrify upgrades, patching, troubleshooting, and disaster recovery activities
- Resolve escalations related to Active Directory bridging and Linux authentication issues
- Maintain clear documentation for Centrify processes, procedures, and operating standards
- Support audits and compliance reviews by providing accurate evidence and documentation
Required Skills:- 5+ years of Linux system administration or engineering experience, including Name Service Switch (NSS), Pluggable Authentication Modules (PAM), and SUDO policy management
- 5+ years supporting Active Directory or cloud bridging solutions such as Centrify or CyberArk Endpoint Privilege Manager (EPM)
- 5+ years automating tasks with PowerShell, Python, Bash, or similar scripting languages
- Self-motivated and able to take ownership of assigned work, independently drive tasks to completion, identify gaps or risks, and proactively learn new Identity and Access Management (IAM) technologies with limited day-to-day direction
Desired Skills:- Experience with Privileged Access Management (PAM) platforms such as CyberArk, CA ePAM, or similar tools
- Experience with Active Directory authentication, Kerberos, LDAP, and related security protocols
- Knowledge of IAM and PAM industry standards and best practices
- Experience integrating with cloud service providers such as AWS, Microsoft Azure, or Google Cloud Platform
- Experience managing Microsoft Entra ID capabilities such as Single Sign-On (SSO), Conditional Access, and Access Packages
- Experience operating in a financial services company
- Excellent verbal and written communication skills
Education:- Bachelor's degree in a related field or equivalent work experience
The typical base pay range for this role is as follows:
- New York / New Jersey: $134k - $168k
- Non-New York / New Jersey: $126k - $150k
depending on job-related knowledge, skills, experience, and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
MUFG Benefits Summary